Cross-site Scripting Vulnerability in Azure DevOps Server and Team Foundation Server
CVE-2019-0979

5.4MEDIUM

Key Information:

Summary

A Cross-site Scripting (XSS) vulnerability has been identified in Azure DevOps Server and Team Foundation Server, stemming from their failure to adequately sanitize user-supplied input. This flaw can potentially allow an attacker to inject malicious scripts that could execute in the context of a user's session, compromising the security of sensitive data and user operations. It is crucial for users of these platforms to apply the necessary security updates to mitigate this risk.

Affected Version(s)

Azure DevOps Server 2019

Team Foundation Server 2017 Update 3.1

Team Foundation Server 2018 Update 1.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.